// For flags

CVE-2021-22054

 

Severity Score

7.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37 contain an SSRF vulnerability. This issue may allow a malicious actor with network access to UEM to send their requests without authentication and to gain access to sensitive information.

La consola VMware Workspace ONE UEM versiones 20.0.8 anteriores a 20.0.8.37, versiones 20.11.0 anteriores a 20.11.0.40, versiones 21.2.0 anteriores a 21.2.0.27 y versiones 21.5.0 anteriores a 21.5.0.37, contienen una vulnerabilidad de tipo SSRF. Este problema puede permitir a un actor malicioso con acceso a la red de UEM enviar sus peticiones sin autenticaciĆ³n y conseguir acceso a informaciĆ³n confidencial

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2021-01-04 CVE Reserved
  • 2021-12-17 CVE Published
  • 2022-06-03 First Exploit
  • 2024-08-03 CVE Updated
  • 2024-09-01 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-918: Server-Side Request Forgery (SSRF)
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Vmware
Search vendor "Vmware"
Workspace One Uem Console
Search vendor "Vmware" for product "Workspace One Uem Console"
>= 20.0.8.0 < 20.0.8.36
Search vendor "Vmware" for product "Workspace One Uem Console" and version " >= 20.0.8.0 < 20.0.8.36"
-
Affected
Vmware
Search vendor "Vmware"
Workspace One Uem Console
Search vendor "Vmware" for product "Workspace One Uem Console"
>= 20.11.0.0 < 20.11.0.40
Search vendor "Vmware" for product "Workspace One Uem Console" and version " >= 20.11.0.0 < 20.11.0.40"
-
Affected
Vmware
Search vendor "Vmware"
Workspace One Uem Console
Search vendor "Vmware" for product "Workspace One Uem Console"
>= 21.2.0.0 < 21.2.0.27
Search vendor "Vmware" for product "Workspace One Uem Console" and version " >= 21.2.0.0 < 21.2.0.27"
-
Affected
Vmware
Search vendor "Vmware"
Workspace One Uem Console
Search vendor "Vmware" for product "Workspace One Uem Console"
>= 21.5.0.0 < 21.5.0.37
Search vendor "Vmware" for product "Workspace One Uem Console" and version " >= 21.5.0.0 < 21.5.0.37"
-
Affected